Defence Cyber Certification, without the complexity.
Working with the Ministry of Defence, or supplying into the UK defence supply chain? Nerdster helps you understand, implement and evidence the cyber security controls required under Defence Cyber Certification (DCC) and DEF STAN 05-138 Issue 4, so you are ready for independent certification.
Defence Cyber Certification (DCC) is the Ministry of Defence's assurance scheme, delivered with IASME, that certifies defence suppliers against the controls in DEF STAN 05-138 Issue 4 at four levels: Level 0 (3 controls, built on Cyber Essentials), Level 1 (101 controls), Level 2 (139 controls) and Level 3 (144 controls), with Cyber Essentials Plus required at Levels 2 and 3. The MOD has asked its industry partners to hold Level 0 by 31 December 2026. Nerdster prepares you for independent assessment with a gap assessment, remediation, policies and an organised evidence pack; the certificate itself is issued by an approved DCC Certification Body.
- 4 levels
- Level 0 to Level 3, matched to your Cyber Risk Profile
- 31 Dec 2026
- The MOD's target for defence suppliers to hold Level 0
- 101 controls
- At Level 1, across the whole organisation, not just the IT
- CE Plus
- Required at Levels 2 and 3; every level builds on Cyber Essentials
Meet the requirements you will be assessed against
Level 0: basic cyber security, 3 controls
For contracts assessed as very low cyber risk. It covers the fundamental security requirements and Cyber Essentials. Nerdster handles Cyber Essentials, the technical checks, remediation and DCC preparation.
Level 1: comprehensive cyber security, 101 controls
For low to moderate cyber-risk environments. Level 1 looks across the whole organisation, not just the IT estate. The full list of control areas is below.
Level 2: advanced cyber security, 139 controls
For work assessed as high cyber risk. Level 2 adds more advanced security oversight, monitoring, resilience and planning. Cyber Essentials Plus is required. We work with your team and specialist certification partners to close the gaps and prepare for assessment.
Level 3: defence in depth, 144 controls
The highest DCC level, for substantial cyber-risk environments. It calls for mature cyber security capability, strong organisational resilience and a defence-in-depth approach against sophisticated, evolving threats. Cyber Essentials Plus is required.
Your Cyber Risk Profile decides the level
The MOD or your prime contractor assigns a Cyber Risk Profile to the work. That profile, not your own preference, sets the DCC level you need. If you have been given one, send it to us and we will explain what it means for your business.
Independent certification, prepared by us
Certification is carried out by an approved DCC Certification Body. Nerdster's role is to get you ready: assess the gaps, implement the controls, build the evidence pack and support you through the assessment.
Get your business ready for DCC. From Cyber Essentials and technical remediation to policies, evidence and assessment preparation, we help you get ready for independent certification. UK-based support, Cyber Essentials expertise, practical implementation and ongoing cyber security.
Book a DCC readiness call · Understand your DCC requirements
What is Defence Cyber Certification?
Defence Cyber Certification is the assurance scheme supporting the Ministry of Defence’s Cyber Security Model. It demonstrates that organisations handling defence work have appropriate cyber security and resilience in place, measured against DEF STAN 05-138 Issue 4.
There are four levels, and the one you need is set by the Cyber Risk Profile attached to the work.
What is DEF STAN 05-138?
DEF STAN 05-138 Issue 4 is the Ministry of Defence’s cyber security standard for the defence supply chain. It sets out the controls behind Defence Cyber Certification: 3 at Level 0, 101 at Level 1, 139 at Level 2 and 144 at Level 3. If a tender, contract or prime-contractor requirement quotes “DEF STAN 05-138” rather than “DCC”, it is asking for the same thing under its formal name.
Each level sets a different bar, summarised in the cards above. Level 0 is the baseline every MOD supplier is expected to reach. Level 1 adds a full, organisation-wide control set for low to moderate risk work. Levels 2 and 3 are reserved for high and substantial risk programmes and require Cyber Essentials Plus on top. The controls scale from 3 at Level 0 to 144 at Level 3, but Cyber Essentials sits underneath every one of them.
Level 1 is where most SME suppliers first feel the difference. Its 101 controls cover:
- Security governance
- Policies and procedures
- Risk management
- Asset management
- User and access controls
- Endpoint security
- Patch management
- Encryption
- Email and network security
- Staff awareness
- Supplier security
- Vulnerability management
- Logging and monitoring
- Incident response
- Business continuity and recovery
Nerdster can help you build and evidence the complete programme, and for Level 2 and Level 3 we work with your internal team and specialist certification partners to identify gaps, implement controls and prepare the organisation for assessment.
Not sure which level you need?
You do not need to decode the Defence Standard yourself.
If an MOD customer, prime contractor or procurement process has given you a Cyber Risk Profile, we review the requirement and explain what it means for your business. If you are preparing ahead of a defence opportunity, we assess your current environment against the appropriate DCC requirements.
From requirement to ready
1. Understand
We review your DCC requirement, Cyber Risk Profile and current cyber security environment. You get a clear explanation of what applies to your organisation.
2. Assess
We compare your existing security against the required controls. Already have Cyber Essentials, ISO 27001, Microsoft 365, Intune or other controls in place? We identify what can be reused and where the real gaps are.
3. Fix
We help implement what is missing. That can include policies and procedures, Microsoft 365 security, Intune and endpoint management, MFA and identity security, access controls, device configuration, patch management, EDR and malware protection, firewalls and network security, encryption, backups and recovery, logging and monitoring, vulnerability management, supplier controls, staff cyber awareness and incident response.
4. Evidence
Having security controls is not enough if you cannot demonstrate them. We build an organised evidence pack showing how each control is implemented and managed.
5. Prepare
Before independent assessment, we work through outstanding issues and help your team prepare for the certification process.
6. Maintain
Cyber compliance is not a once-a-year scramble. Nerdster can continue managing your IT, cyber security, monitoring, policies and evidence so your environment stays ready.
Already have Cyber Essentials?
Good. You already hold part of the foundation, and at Level 0 most of it. Above that, DCC asks about how the whole business runs its security: who owns risk, how suppliers are vetted, what happens when something goes wrong. Nerdster helps bridge that gap.
- Cyber Essentials. basic technical cyber hygiene. See our Cyber Essentials packages.
- DCC readiness. technology, people, processes, policies, evidence and resilience.
- Independent DCC assessment. Assessment and certification through an approved DCC Certification Body licensed by IASME.
What you get
- DCC gap assessment. a structured review against the controls applicable to your required DCC level.
- Readiness score. where you are today, what is already covered and what still needs attention.
- Remediation plan. a prioritised action plan instead of a 100-page compliance document nobody understands.
- Technical implementation. where required, Nerdster implements and manages the underlying security technology.
- Policies and procedures. the governance and operating procedures the controls call for.
- Evidence pack. evidence organised against the relevant controls, ready for assessment preparation.
- Certification support. we work alongside your chosen independent DCC Certification Body through the certification process.
- Ongoing management. your security controls kept maintained after certification.
Already using Microsoft 365?
You may be closer than you think. For many SMEs, capabilities already available within Microsoft 365, Entra and Intune contribute to identity, MFA, device management, access control, security configuration, endpoint protection, logging and data protection.
The challenge is configuring them correctly, documenting them and filling the gaps around them. That is where Nerdster comes in — see our Microsoft 365 support.
Built for SMEs in the defence supply chain
You should not need a full-time compliance department just to understand what your MOD customer is asking for. Nerdster combines IT, cyber security and practical compliance implementation into one service, and focuses on getting the controls working in the real business, not on producing policies for a folder.
- We implement the changes ourselves rather than handing you a list of what is wrong.
- You always know what is complete, what is missing and what happens next.
- If you want, we keep running the underlying security controls after the project finishes.
- Support comes from a UK technology and cyber security team.
DCC readiness packages
DCC Level 0 readiness
For organisations requiring the foundation level of Defence Cyber Certification. Includes a Cyber Essentials review, technical gap assessment, remediation support, DCC readiness review, evidence preparation and certification coordination.
DCC Level 1 readiness
For organisations that need to demonstrate a comprehensive cyber security programme against the Level 1 controls. Includes a full control gap assessment, technology review, policy and governance review, risk and asset management, security remediation, evidence mapping, staff and supplier requirements, incident and recovery preparation, a pre-assessment review and certification coordination.
Level 2 and Level 3
Higher DCC levels require considerably more advanced cyber security capability and Cyber Essentials Plus. Talk to us about your requirement and we will help establish the right programme.
Do not wait for a defence opportunity to expose the gaps
Whether you have already been given a DCC requirement or simply want to become ready to supply the defence sector, we will show you where you stand and what needs to happen next. Start with a DCC readiness review: understand your current position, identify the gaps and build a clear route to certification.
Last updated:
FAQ
Frequently asked questions
Do I need DCC to work with the MOD?
It depends on the contract and the Cyber Risk Profile assigned through the MOD Cyber Security Model. The MOD has asked its industry partners to hold Level 0 by 31 December 2026, and higher levels are set per contract. If DCC or Defence Standard 05-138 appears in a tender, contract or prime-contractor requirement, send it to us and we will explain what is required.
What is DEF STAN 05-138?
DEF STAN 05-138 Issue 4 is the Ministry of Defence's cyber security standard for its supply chain, and the formal name behind Defence Cyber Certification. DCC is the independent certification against it; the level you need is set by the Cyber Risk Profile of the work.
Is DCC the same as Cyber Essentials?
No. Cyber Essentials is part of the foundation, but DCC covers a much wider set of organisational cyber security requirements. All DCC levels build on Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus.
Can Nerdster certify us?
No. Independent DCC certification is carried out by an approved DCC Certification Body. Nerdster's role is to make you ready: assess the gaps, implement the controls, prepare the evidence and support you through the certification process.
We already have ISO 27001. Do we need to start again?
Not necessarily. DCC shares control areas with ISO 27001, NIST and Cyber Essentials. We identify the controls and evidence you already hold that can be reused before recommending any additional work.
We do not have an internal IT or cyber team. Is that a problem?
No. Nerdster can implement and manage the technology and security controls as your outsourced IT and cyber security partner, and keep them maintained after certification.
Talk to our team about this standard
Tell us where you are with this standard. A London-based engineer replies within 2 hours during business hours.
Message sent
Thanks for getting in touch. We will reply within 2 hours on a business day.
Contact details
0330 043 7414
Mon-Fri 8am-6pm
hello@nerdster.co.uk
We reply within 2 hours
71-75 Shelton Street
Covent Garden, London WC2H 9JQ
IT assessment
A review of your IT, your security posture and your compliance readiness, free of charge.
- 30-minute consultation call
- Infrastructure & security review
- Compliance gap analysis
- Custom recommendations report
Related compliance services
Find out where you stand today
Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.
- No callout fees
- No-obligation assessment